Skip to content

DPC AI Insights Report: key takeaways

On 24 September 2026, the Data Protection Commission (“DPC”) published its report on Responsible Artificial Intelligence Innovation (the “Report”).  The Report provides an insight into the DPC’s supervisory engagement with organisations developing and deploying artificial intelligence (“AI”) products and services in the EU between 2021 and 2025.

While AI impacts on all sectors, the Report focuses on DPC engagements with the large multinational tech companies based in Ireland.  The DPC is in a unique position in Europe given its role as Lead Supervisory Authority (“LSA”) for many of the world’s largest technology companies with European headquarters located in Ireland.

The DPC reports a tenfold increase in AI-related supervisory engagements with large technology controllers during 2021-2025, driven in part by the rapid development of generative AI.  In fact, by 2025, 1 out of every 4 DPC supervision engagements with large technology controllers were AI-related.

The Report highlights that these DPC engagements have secured significant improvements in data protection compliance in the areas of lawful basis, transparency, data minimisation, and the protection of children’s personal data.  The DPC notes the application of legitimate interests as a legal basis for AI training as a significant area of regulatory focus, alongside the need for robust transparency having regard to the novel and often opaque nature of AI processing activities.

DPC supervision of AI

The Report notes that in 2025, 52.7% of EU firms which considered using AI technologies and chose not to, cited data protection and privacy concerns as a reason why.  Accordingly questions related to data protection and privacy will be paramount for further AI development and diffusion, and the Report highlights that the DPC can be of assistance in its consultative and awareness-raising capacity.

The DPC Supervision Function operates separately from the complaints and inquiry functions. The Report notes that the DPC Supervision Function operates as a ‘quasi-regulatory sandbox’ allowing the DPC to engage voluntarily with controllers and identify significant risks and influence product design at the pre-processing stage (i.e before a product or service launches).  The objective is to ensure that a data protection by design and by default approach is embedded into product design at the earliest juncture of product development, and that significant risks and harms are identified before the launch of new products and services into the European market.

The Report notes that between 2021 and 2025, the DPC engaged with controllers in relation to development, launch and deployment of approximately 180 AI products and services, including large language models (“LLMs”), recommender systems, age assurance, facial recognition, personalisation and AI agents.  Whilst generative AI was involved in 79% of all AI engagements during this period, non-generative AI (including age assurance and facial recognition engagements etc.) accounted for 21% of all engagements.

What does supervisory engagement entail?

The Report notes that the DPC is conscious that there is no one-size fits all approach for many aspects of data protection compliance under the GDPR, and this also applies in respect of supervision engagements.  The DPC has reportedly used the full range of regulatory functions as part of its engagements, ranging from making recommendations, requesting controllers to pause a proposed launch, and obtaining court orders to cease processing, via urgency action powers.

These engagements typically involve an assessment of a product or of proposed processing from a high-level, high-risk perspective, but the DPC will never approve or state that a process, product or service is compliant with the GDPR during these engagements. However, engaging with the DPC ensures that controllers are well positioned to achieve compliance prior to a product or service launch,  mitigate the risks of non-compliance, and mitigate the risk of a DPC investigation or inquiry.

These engagements can also involve controllers consulting with the DPC in respect of a Data Protection Impact Assessment (“DPIA”), Legitimate Interests Assessment (“LIA”), or other risks assessments in relation to the proposed product / service, and the DPC consulting with other EU supervisory authorities, making recommendations and monitoring products following launch.

The Report suggests that organisations engage with the DPC Supervision Function at an early stage, in order to allow the DPC to assess the documentation, ensure that design choices align with GDPR requirements and for controllers to address and implement the DPC’s recommendations ahead of a product launch.  The DPC considers a minimum eight-week lead time is prudent in order to facilitate a substantive engagement.  In 2024 and 2025 combined, 59% of all AI products or services that launched in the EU were issued with recommendations.

What happens if DPC supervisory engagement finds evidence of non-compliance?

Where significant or ‘red line’ issues are identified, and the DPC’s (non-binding) recommendations are not implemented, the DPC may consider exercising other regulatory powers.  In addition, the DPC may request that a controller voluntarily pauses processing, including where significant compliance concerns have been identified or additional time is required to complete the engagement.  Notably, between 2021 and 2025, nine AI-related launches were delayed or cancelled following DPC engagement.  However, the DPC states that 95% of AI engagements proceeded to product launch without delay due to DPC engagement.

Where the DPC considers that processing presents a real risk to individuals’ rights and freedoms and urgent intervention is required, the DPC may exercise its powers under Section 134 of the Data Protection Act 2018 (“the 2018 Act”). That provision enables the DPC to seek an order from the High Court suspending, restricting or prohibiting the processing of the relevant personal data. The DPC may also commence a formal inquiry under Article 58 GDPR, where non-compliance is identified concerning the ongoing processing of personal data.  The Report confirms that the DPC has utilised this power in relation to a number of AI engagements. In particular, two leading international technology companies are subject to an ongoing inquiry by the DPC in regard to their processing of personal data of EU/EEA data subjects associated with their AI models.  Accordingly, the Report notes that although supervision is engagement-led, the DPC may exercise its formal regulatory powers where identified risks are not adequately addressed.

Advocating guidance

The Report highlights that the benefits of DPC supervisory engagement go beyond driving better GDPR compliance by controllers.  In particular, the DPC has been able to leverage the insights gained through its supervisory engagement to advocate for guidance from the European Data Protection Board (“EDPB”) in relation to AI. For example, in summer 2023, it became clear to the DPC that there were a number of differing opinions, interpretations, and understandings when it came to processing personal data for the training of AI. This led to the DPC’s request for an Article 64(2) GDPR opinion from the EDPB on the legal basis for AI training.  The resulting EDPB Opinion 28/2024, provided general criteria that the DPC and all other EU supervisory authorities should take into account when assessing compliance of the processing of personal data for the development and deployment of AI models. The DPC notes that it continues to use this Opinion to provide consistent guidance to controllers, including in relation to a controller’s reliance on legitimate interests under Article 6(1)(f) GDPR as a possible legal basis for processing personal data for the purposes of AI training.

Proactive and ongoing monitoring, and good documentation

Supervisory engagement and data protection compliance does not end when an AI product or service is launched.  Compliance can become an issue in the deployment phase as well, and the DPC engages in ongoing monitoring of high risk systems post-launch.

The Report highlights that on the emergence of mainstream generative AI models in 2023, the DPC developed an AI Questionnaire, proactively seeking responses from controllers as to their future plans and developments regarding the creation of generative AI.  In addition, the DPC requested reports from controllers creating and deploying LLMs.  These reports required controllers to gather live data to evaluate the performance of LLMs; the effectiveness of technical and organisational safeguards; reactions of individuals or the wider public; and other real-world issues that may impact on the privacy of the AI or AI system.

All reports have required a controller to re-evaluate the original risk assessments, DPIAs, LIAs (where applicable) and other risk assessments in light of post-deployment evidence, identify shortcomings, and implement additional safeguards, where appropriate.  A number of controllers have reportedly confirmed these reports are helpful to them, but have also used them as a means of evidencing data protection compliance.

The Report highlights the importance of controllers compiling detailed compliance documentation, evidencing the choices and decisions made by the controller.  Good documentation enables controllers to demonstrate compliance with the accountability principle under Article 5(2) GDPR and facilitates speedy regulatory engagements.  Conversely, high-level assertions of data protection compliance by controllers, which are not supported by sufficient evidence or reasoning, may prolong supervisory engagement and delay or pause a product launch.

DPC observations regarding AI technologies

The Report provides helpful observations and insights into the issues most frequently arising during DPC supervisory engagements concerning the processing of personal data in the context of the development and deployment of AI. These issues include the importance of compliance with data protection obligations relating to (i) transparency, (ii) legal basis and legitimate interests, (iii) right to object, (iv) data minimisation, (v) AI and children, and (vi) automated decision-making.

    • Transparency

Transparency issues have been present in 72% of all recommendations made by the DPC Supervision Function .  The DPC considers that transparency should always be provided both in the creation and deployment phase.  The DPC has found this to be an area that many controllers do not adequately consider when designing transparency notices, especially in respect of the use of personal data for AI training. The onus is therefore on controllers to educate individuals on the data protection implications and risks of AI technologies.

The DPC notes that inadequate transparency notices may undermine reliance on legitimate interests or the validity of consent as a legal basis for processing. This transparency obligation extends to non-users whose personal data may be processed, and may require the use of multiple appropriate communication channels.

    • Legal basis and legitimate interests

The DPC identifies the application of an appropriate legal basis for processing personal data in an AI context as a significant consideration. While the legal basis under Article 6 GDPR featured in only 7% of the data protection issues raised in recommendations, these recommendations were reportedly often expansive and of critical importance to a controller’s compliance.

The EDPB Opinion 28/2024 confirmed that legitimate interests under Article 6(1)(f) GDPR may be relied on for AI development and training in certain circumstances.  The DPC Supervision Function has undertaken a detailed analysis of claims to rely on Article 6(1)(f) GDPR in relation to AI training. This has involved an analysis of LIAs by controllers to determine if a controller has met the three-step test.

This three-step test, includes: (i) identifying the legitimate interests pursued; (ii) considering the necessity of the processing in order to pursue those legitimate interests, and (iii) carrying out a balancing test to assess whether the rights and freedoms of data subjects outweigh the controller’s legitimate interests.  The Report places particular focus on individuals’ reasonable expectations, especially where historical personal data is repurposed for AI training.  In order to rely on legitimate interests as a legal basis for processing, a controller must, as part of the balancing test, take account of the reasonable expectations of data subjects. Furthermore, given that there is an inherent expectation of privacy in respect of private communications, the DPC indicates that reliance on legitimate interests as a legal basis to use private messages for AI training purposes would likely be difficult to justify.  In addition, controllers would have to demonstrate that any usage of private messages for AI training does not breach the ePrivacy Directive, which requires the confidentiality of communications to be guaranteed.

    • Right to object

Where controllers rely on legitimate interests under Article 6(1)(f) GDPR to process personal data for the purpose of AI training, individuals must be afforded the right to object under Article 21 GDPR.  This right to object has featured across 7% of data protection issues raised in DPC recommendations.   Taking into consideration the difficulty of removing any training data once an AI model is trained, the DPC highlights that objection mechanisms must be easily accessible and made available with sufficient notice before processing begins. The DPC warns that any friction to access an objection form or method should be minimised to the greatest extent possible.

    • Data minimisation

The DPC recognises that particular challenges arise in regard to applying the data minimisation principle under Article 5(1)(c) GDPR to AI model training which requires large volumes of data.  Taking this into account, the DPC recommends that controllers should ensure that personal data used for AI training is limited to what is necessary, including through measures such as pseudonymisation or anonymisation of a dataset; de-duplication; limiting the timeframe of collection;  and avoiding training on the personal data of individuals under 18 years of age, or sources with a likely prevalence of sensitive personal data.  Data minimisation also applies throughout the deployment of AI models.

    • AI and children

The DPC identifies the protection of children’s personal data as a particular priority in the development and deployment of AI.  Controllers should ensure that information about AI processing and associated risks is presented to children in clear, accessible and age appropriate language.  The DPC notes that AI terminology such as ‘hallucinations’ or ‘machine learning’ may not be understandable to a young person, and finding an appropriate level of transparency for different age cohorts has been challenging for controllers.

The DPC has made a number of recommendations in respect to protection children’s personal data, including: enhanced transparency at onboarding; clearer transparency using plain English and explaining terms used; and ensuring the risks posed by AI are clear.  For six controllers, in relation to seven different AI products / services, the DPC has recommended they provide greater transparency to children on data protection risks and ongoing in-app transparency to support children in learning about tools to check the veracity of generative AI outputs.

The Report notes that the majority of engagements involving the development of AI models, have seen controllers choose not to process the personal data of children for AI training.  Further, where a user’s data becomes eligible for AI training upon turning 18 years of age, the DPC expects the individual to receive appropriate notice and transparency, along with an opportunity to object before the processing begins.

    • Automated decision-making

In some instances, AI may involve automated decision-making under Article 22 of the GDPR.  Accordingly, controllers should ensure that data protection is embedded in the design and deployment of AI systems.  This supports compliance with the data protection by design and default requirements in Article 25 GDPR, and is imperative to avoiding any prohibited solely automated decision-making.

Comment

Whilst the Report focuses on DPC supervisory engagement during 2021-2025, the DPC has continued to engage intensively with controllers developing and deploying AI technologies over the past year. The Report also highlights that agentic AI is a rapidly growing area of engagement for the DPC. The DPC has issued recommendations on a number of agentic AI engagements.  Whilst the common themes across controllers are not yet clear, the Report notes a lack of transparency and clarity on how AI agents are processing personal data; how AI agents work; and their potential impact on users’ rights.

The Report sets out the scope of the DPC’s activities in regulating emerging AI technologies under the GDPR and the 2018 Act, and provides a clear indication of the standards the DPC expects AI developers and deployers to meet to ensure GDPR compliance.  It also reminds organisations of the importance of early engagement with the DPC, in order to ensure sustainable, responsible data protection and privacy-centric innovation.

Contact us

For more information regarding the Report, or artificial intelligence generally, please contact any member of our Technology and Innovation Group or your usual Matheson contact.

© 2026 Matheson LLP | All Rights Reserved